Security & Compliance

Patient data, protected by design.

Arogyam.ai safeguards every record with bank-grade encryption, strict access controls, and full audit trails — built for India's DPDP Act, 2023, engineered to HIPAA Security Rule standards, and designed to be ABDM-ready.

AES-256 encrypted Data resident in India Every access audit-logged
DPDP-Aligned
HIPAA-Grade Safeguards
AES-256 Encryption
India Data Residency
ABDM-Ready

Compliance, the way Indian clinics actually need it

Patient records are among the most sensitive data a clinic holds. Protecting them is not a feature you bolt on — it is how the whole system is built. Arogyam.ai approaches data protection through three lenses that matter for a modern Indian practice: the law that governs you, the global engineering standard we hold ourselves to, and the national health network you'll grow into.

Your governing law is the DPDP Act. For clinics operating in India, the Digital Personal Data Protection Act, 2023 sets the rules for how patient data is collected, used, and protected. HIPAA is the international benchmark. While HIPAA is a United States law, its Security Rule has become the world's reference standard for health-data safeguards — and we engineer Arogyam to meet it. ABDM is India's digital-health network. We keep records ABHA-ready and FHIR-compatible so your clinic is positioned to connect to the Ayushman Bharat Digital Mission.

Three Frameworks, One Standard of Care

Built for India. Held to the world's standard.

How Arogyam.ai maps to the frameworks that protect your patients — and your practice.

DPDP Act, 2023 — your law

Built around the DPDP Act's core duties: consent-based processing, purpose limitation, the rights of the data principal (your patient), and clear safeguards against misuse — with data held inside India.

HIPAA-grade safeguards

Engineered to the HIPAA Security Rule's administrative, physical, and technical safeguards — the international gold standard for health-data security. A Business Associate Agreement (BAA) is available where applicable.

ABDM-ready architecture

Records are kept structured, HL7 FHIR-compatible, and ABHA-ready, so your clinic is positioned to connect with India's ABDM digital-health network.

Under the Hood

How we protect your patients' data.

The concrete controls behind every record in Arogyam.ai. Scroll to walk through each layer of protection.

Talk to our team →

Encryption at rest

Sensitive patient data is encrypted with AES-256 using envelope encryption managed by Google Cloud KMS, so records are unreadable even at the storage layer.

Encryption in transit

Every connection is secured with TLS 1.3, so patient data is protected as it travels between your browser and our servers.

Role-based access

Least-privilege access controls mean doctors, front-desk, billing, and lab staff see only the data their role needs — nothing more.

Full audit trail

Access to patient records is logged. A tamper-evident audit trail records who viewed or changed what, and when.

India data residency

Patient data is hosted on Google Cloud infrastructure within India, in ISO 27001-certified data centres.

Backups & resilience

Encrypted, automated backups and disaster-recovery processes keep your records safe and available if the unexpected happens.

No data sales — ever

Your patients' data is used only to run your clinic. It is never sold, rented, or shared with third parties for advertising.

Hardened infrastructure

Built on Google Cloud — physically secured, continuously monitored, and certified to ISO 27001 and SOC 2 standards.

Consent-first framework

Patient data is processed on a consent-first basis — consent is captured, recorded, and revocable — in line with the DPDP Act's consent and purpose-limitation principles.

The HIPAA Security Rule, Mapped

Three layers of safeguards.

The HIPAA Security Rule groups protections into three categories. Here's how Arogyam.ai addresses each.

Technical safeguards

Unique user logins and role-based access, AES-256 encryption at rest and TLS in transit, audit logging of record access, and integrity controls so data can't be silently altered.

Administrative safeguards

Access is provisioned by role on a least-privilege basis, with internal processes for risk review, change management, and responding to security incidents.

Physical safeguards

Data lives in Google Cloud data centres within India, with 24/7 physical security, environmental controls, and ISO 27001 / SOC 2 certification.

Questions Answered

Security & compliance FAQs.

Is Arogyam.ai HIPAA compliant?
Arogyam.ai is engineered to meet the administrative, physical, and technical safeguards of the HIPAA Security Rule — AES-256 encryption, role-based access controls, and full audit logging — and we can provide a Business Associate Agreement (BAA) where applicable. For clinics in India, your practice is primarily governed by the DPDP Act, 2023, which Arogyam is built to support.
Is Arogyam.ai compliant with India's DPDP Act, 2023?
Yes. Arogyam.ai is built around the DPDP Act's principles — consent-based processing, purpose limitation, data-principal rights, and safeguards against breaches — with all patient data hosted within India.
Is Arogyam.ai integrated with ABDM?
Arogyam.ai keeps structured, HL7 FHIR-compatible, ABHA-ready records and is designed to connect with India's Ayushman Bharat Digital Mission (ABDM), so your clinic is positioned to adopt ABHA-linked records as part of the national digital-health ecosystem.
Where is my patient data stored?
All patient data is hosted on Google Cloud infrastructure within India (data residency), in ISO 27001-certified data centres.
What encryption does Arogyam.ai use?
Sensitive patient data is encrypted at rest with AES-256 (envelope encryption managed by Google Cloud KMS) and in transit with TLS 1.3.
Does Arogyam.ai sell or share patient data?
Never. Patient data is used only to provide the service to your clinic. It is never sold, rented, or shared with third parties for advertising.
We're Happy to Go Deeper

Have a security or compliance question?

Whether you need a BAA, a security overview for your team, or details on data residency — talk to us. We'll give you straight answers.